What is CVE-2026-14356?
The FleekDash V2 plugin for WordPress (up to version 2.6.2.2) contains an authorization bypass vulnerability. Due to improper verification of user permissions, authenticated attackers with subscriber-level access can perform unauthorized actions. Immediate update to the latest version is recommended.
Azərbaycanca: FleekDash V2 WordPress plaqini (2.6.2.2 versiyasına qədər) avtorizasiya zəifliyinə malikdir. Plaqin istifadəçi səlahiyyətlərini düzgün yoxlamadığı üçün, abunəçi səviyyəli autentifikasiya olunmuş hücumçular icazəsiz əməliyyatlar həyata keçirə bilər. Plaqini dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Who can exploit the CVE-2026-14356 vulnerability in the FleekDash V2 WordPress plugin?
Authenticated attackers with subscriber-level access can exploit this vulnerability.
How can I protect against CVE-2026-14356?
It is recommended to immediately update the FleekDash V2 plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.